CVE-2025-38562
—CVSS 3.1
5.5 medium
EPSS
8%p95
Published
()
Modified
Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in generate_encryptionkey If client send two session setups with krb5 authenticate to ksmbd, null pointer dereference error in generate_encryptionkey could happen. sess->Preauth_HashValue is set to NULL if session is valid. So this patch skip generate encryption key if session is valid.
In the news0 stories
No ingested article mentions this CVE yet.